Use this skill when the user asks for a review, audit, evaluation or analysis of a codebase, to identify bugs, security vulnerabilities, outdated dependencies or runtimes, performance bottlenecks, or code quality concerns.
Security-first dependency hygiene for Node and Python projects. Use when auditing dependencies, verifying automated dependency updates, reviewing or editing manifests and lockfiles, triaging vulnerability findings, handling supply chain incidents, or maintaining long-term dependency safety practices.
Implement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilities.
Use for expert engineering judgment, "X mode", seasoned/staff/principal standards, robust architecture, security/performance/reliability/scalability scrutiny, optimization review, rigorous implementation/release discipline, or implementation with implement-release-flow. A rigor overlay for design, testing, reviews…
Assess whether a specific ERC-8004 agent is trustworthy and capable, using the Agent Scan backend. Use this whenever the user wants to evaluate, vet, or do due diligence on an agent before trusting/hiring it. Triggers: "is this agent reliable", "vet this agent", "should I trust agent X", "due diligence on agent"…
An audit tool for recording versioned agent events, linking them with hashes and HMAC signatures, and protecting stored data through redaction or summaries. HMAC is a way to detect changes using a secret key.
Use when you are given a company name, domain, or short description and need to determine which cybersecurity regulations, compliance frameworks, and data-protection laws apply to it — and which of those obligations mandate security testing, VAPT, red-teaming, or continuous control validation.
Evaluate AI agent configurations, plugin skill files, MCP server connections, and tool permissions for security risks. Use this skill whenever the user mentions scanning plugins, reviewing agent security, auditing AI tools, evaluating MCP configurations, checking skill files for vulnerabilities, prompt injection…
Guides Claude to act as an expert ERP security analyst using SyntaAI ERP Security MCP tools. Enables comprehensive SAP security audits, compliance assessments, and user access reviews through natural conversation.
Use psamvault MCP server: credential vault, browser login, API key injection, .env secret protection. MCP tools keep secrets out of the agent's context window.
Use when an agent can run shell commands and needs secure short-lived human surveys. Secure E2EE via uvx is the default; plaintext is explicit opt-in only.
Audit local Docker images and running containers for hardening issues before deploy — privileged flags, root users, stale base images, missing resource limits. Use for pre-deploy container review.
Comprehensive guide for setting up and configuring CodeQL code scanning via GitHub Actions workflows and the CodeQL CLI. This skill should be used when users need help with code scanning configuration, CodeQL workflow files, CodeQL CLI commands, SARIF output, security analysis setup, or troubleshooting CodeQL analysis.
Deterministic EVM bytecode capability observations, EIP-1967 proxy resolution, gas recommendations, and sourced telemetry for autonomous applications on Base (Chain ID 8453).
★not rated 2▲
+1 5d agoA42 tokens
originalMIT
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: